UHUBS POLICY

Identity & Access Management Policy

Last reviewed on 30 October 2025
Uhubs' Identity & Access Management Policy includes the Principle of Least Privilege through Role-Based Access Control, Multi-Factor Authentication, use of VPNs for secure remote access, implementation of Single Sign-On, guidelines on strong passwords, and regular access reviews to maintain a secure access environment.

1. Principle of Least Privilege:

1.1 Role-Based Access Control (RBAC):

Uhubs adopts a strict Principle of Least Privilege through RBAC, ensuring that access permissions are tailored to each employee's specific role. Access is granted based on job responsibilities, minimizing unnecessary privileges and mitigating potential security risks.

2. Multi-Factor Authentication (MFA):

2.1 Enforcement and Encouragement:

MFA is enforced on critical tools and strongly encouraged on others. Uhubs employs industry-leading MFA solutions to enhance account security. Employees are empowered to enable MFA on their accounts, fortifying authentication processes and safeguarding against unauthorized access.

3. Use of VPNs:

3.1 Secure Remote Access:

Uhubs prioritizes the use of Virtual Private Networks (VPNs) for secure remote access to internal systems where sensible. This ensures encrypted communication, protecting sensitive data during remote work scenarios. Employees are provided with clear instructions on VPN usage to maintain a secure connection.

4. Use of Single Sign-On (SSO):

4.1 Streamlined Access Management:

Uhubs encourages Single Sign-On (SSO) to streamline access management. This enhances user convenience by allowing employees to use a single set of credentials for multiple applications. SSO implementation simplifies onboarding processes and reinforces secure access practices.

5. Guidelines on Strong Passwords (Password Policy):

5.1 Complexity and Regular Updates:

Uhubs maintains a robust password policy that mandates strong passwords. Passwords must include a combination of uppercase and lowercase letters, numbers, and special characters. Employees are required to update their passwords regularly, enhancing overall account security.

6. Review Frequency:

6.1 Regular Access Reviews:

To ensure ongoing adherence to security principles, Uhubs conducts regular access reviews. Access permissions are reviewed periodically to align with employee roles and responsibilities. This proactive approach helps identify and address any unauthorized access, contributing to a continuously secure access environment.

7. Regular Policy Review and Updates:

Uhubs places a strong emphasis on the regular review and update of the policy. An annual review process will be in place to assess the plan's alignment with the evolving environment. This commitment ensures that the policy remains current, adaptable, and effective in addressing emerging challenges and maintaining adherence.

No items found.